Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9rpw-6ghh-qx6q

Опубликовано: 12 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The software does not neutralize or incorrectly neutralizes certain characters before the data is included in outgoing HTTP headers. The inclusion of invalidated data in an HTTP header allows an attacker to specify the full HTTP response represented by the browser. An attacker could control the response and craft attacks such as cross-site scripting and cache poisoning attacks.

The software does not neutralize or incorrectly neutralizes certain characters before the data is included in outgoing HTTP headers. The inclusion of invalidated data in an HTTP header allows an attacker to specify the full HTTP response represented by the browser. An attacker could control the response and craft attacks such as cross-site scripting and cache poisoning attacks.

EPSS

Процентиль: 31%
0.00118
Низкий

7.5 High

CVSS3

Дефекты

CWE-93

Связанные уязвимости

CVSS3: 7.5
nvd
почти 2 года назад

The software does not neutralize or incorrectly neutralizes certain characters before the data is included in outgoing HTTP headers. The inclusion of invalidated data in an HTTP header allows an attacker to specify the full HTTP response represented by the browser. An attacker could control the response and craft attacks such as cross-site scripting and cache poisoning attacks.

EPSS

Процентиль: 31%
0.00118
Низкий

7.5 High

CVSS3

Дефекты

CWE-93